Lifestyle
EU Cyber Resilience Act Reporting Obligations Begin September 11: Who Must Report, How Fast
On September 11, 2026, the reporting obligations under Article 14 of the EU's Cyber Resilience Act took effect, and ENISA launched its Single Reporting Platform. Based on the European Commission's reporting page, ENISA's press release and FAQ, and the Regulation's text in the Official Journal, this article explains how fast manufacturers must report, where reports go, which obligations already apply, which wait until December 2027, and the fine ceiling in Article 64.
About 14 min read

On September 11, 2026, the reporting obligations under the EU's Cyber Resilience Act (Regulation (EU) 2024/2847) took effect: the European Union Agency for Cybersecurity (ENISA) simultaneously launched its Single Reporting Platform (SRP), letting manufacturers report actively exploited vulnerabilities and severe incidents under Article 14. The Regulation itself splits ‘application’ into three dates, and September 11 is only one of them.
This article was fact-checked on September 17, 2026, drawing on the European Commission's reporting-obligations page, ENISA's launch press release and FAQ, and the Regulation's full text as published in the Official Journal of the European Union. This site has not actually submitted a notification or tested the platform itself; the following does not compare vendors or advise on whether to upgrade a device, and only summarizes the officially published provisions and deadlines.
The Three Dates in Article 71(2): September 11 Is Only Article 14's Turn
Article 71(2) of the Cyber Resilience Act splits ‘application’ into three dates: the Regulation applies in full from December 11, 2027 in principle; Article 14 (manufacturers' reporting obligations) applies earlier, from September 11, 2026; and Chapter IV (Articles 35 to 51, on the notification of conformity assessment bodies) applies earlier still, from June 11, 2026.
Only Article 14 takes effect on September 11, 2026. The European Commission's page states it plainly: manufacturers must report actively exploited vulnerabilities and severe incidents affecting product security from September 11 onward; open-source software stewards take on the same obligation under Article 24(3), but only to the extent they are involved in developing the product, and under Article 71(2) their obligation does not begin until December 11, 2027 — ENISA's FAQ likewise keeps the two starting dates separate.
The Regulation was signed in Strasbourg on October 23, 2024, and published in the Official Journal of the European Union on November 20 of the same year; under the formula in Article 71(1), it entered into force on the twentieth day after publication. ‘Entering into force’ and ‘what the provisions require you to do’ are two different things — every sentence that follows in this article notes whether it is already in effect on September 11 or waits until December 11, 2027.
How Fast a Notification Must Go Out, Once You Know
The clock starts running when the manufacturer becomes aware, not from the moment the vulnerability or incident actually occurs. ENISA's FAQ is explicit: the reporting process starts when a manufacturer — or, once it applies, an open-source software steward — becomes aware of it. Article 3(42) defines an ‘actively exploited vulnerability’ as one for which there is reliable evidence that a malicious actor has exploited it without the system owner's permission — merely knowing a weakness exists does not, on its own, trigger the notification obligation under Article 14(1).
Actively exploited vulnerabilities and severe incidents share the same early-warning and full-notification deadlines, but the formula for the final report differs. Under Article 14(2): without undue delay, and in any case within 24 hours of becoming aware, the manufacturer sends an early warning; within 72 hours, a full notification; and the final report follows within 14 days after a corrective or mitigating measure becomes available. Under Article 14(4), the final report for a severe incident instead falls due within one month after the 72-hour notification itself is submitted — the clock there starts from the notification, not from the moment of awareness, and the 14-day rule does not apply.
Article 14(6) gives the CSIRT one more power: if the CSIRT that received the notification considers it necessary, it may ask the manufacturer for an intermediate report describing a status update — a possible fifth document alongside the early warning, the full notification, and the final report. The European Commission's reporting page condenses these four deadlines into a single sentence.
| Stage | Deadline | Starting Point | Legal Basis |
|---|---|---|---|
| Early warning | Within 24 hours | Manufacturer becomes aware of the vulnerability or incident | Article 14(2)(a), 14(4)(a) |
| Full notification | Within 72 hours | Manufacturer becomes aware of the vulnerability or incident | Article 14(2)(b), 14(4)(b) |
| Final report (vulnerability) | Within 14 days of the measure being available | Corrective or mitigating measure becomes available | Article 14(2)(c) |
| Final report (incident) | Within 1 month of the 72-hour notification | Submission of the 72-hour full notification | Article 14(4)(c) |
Where a Notification Goes: One Window, Copied to ENISA
A notification is submitted through the Single Reporting Platform only once. Under Article 14(7), the manufacturer submits it through the electronic notification end-point of the CSIRT designated as coordinator for the Member State of its main establishment in the EU, made simultaneously accessible to ENISA; the Commission notes this holds except in particularly exceptional circumstances. ‘Main establishment’ looks first at the Member State where decisions about product security are made; where that cannot be determined, it looks instead at the Member State with the most employees.
For a manufacturer with no main establishment in the EU, Article 14(7) has it work through one of four fallback identities in order: the Member State of the authorised representative handling the largest number of its products, the Member State of the importer placing the largest number of its products on the market, the Member State of the distributor supplying the largest number of its products, or the Member State with the most users. ENISA warns that the consequence of picking the wrong window is not minor: the notification may be invalidated and have to be resubmitted to the correct one.
The CSIRT that receives a notification forwards it to the CSIRTs of the other Member States where the product is on the market, and supplies market surveillance authorities with the information they need — that is the substance of Article 16. Article 71(2)'s list of provisions that apply early covers only Article 14 and Chapter IV; Article 16 is not on it. Even so, both the Commission and ENISA state that the platform was built under Article 16 and has been operating since September 11. In exceptional cases the CSIRT may delay forwarding; the Commission notes that a delegated act adopted on December 11, 2025 sets out the conditions for that delay.
What This Means for Users and Devices Already Sold
Devices already sold are not exempt. ENISA's FAQ states that the Article 14 reporting obligation ‘will apply from 11 September 2026 to all products with digital elements falling within the scope of the CRA, including products that were placed on the market before 11 December 2027.’ For a router, camera, or wearable bought a few years ago — as long as it is sold on the EU market — the manufacturer must report now if it faces an actively exploited vulnerability or a severe incident, without waiting for the Regulation's full application in December 2027.
Article 14(8) requires the manufacturer, once it becomes aware, to inform affected users of the vulnerability or incident, together with any risk-mitigation and corrective measures where necessary, in a structured, machine-readable format where appropriate. The official pages this article consulted set no deadline, language, or channel for that notice. A likely point of confusion: the reporting obligation does not mean ‘a device will get a patch faster’ — that falls under Article 13's maintenance-period rules, which likewise do not apply until December 11, 2027, and the official pages this article consulted do not say that the reporting obligation taking effect will speed up patches.
A reported vulnerability is not automatically made public: under Article 17(5), ENISA adds a publicly known vulnerability to the European vulnerability database (EUVD) only once a corrective or mitigating measure is available and the manufacturer agrees. As for penalties, Article 64 sets a ceiling of up to €15 million, or 2.5% of an offending undertaking's total worldwide annual turnover for the preceding financial year, whichever is higher, for breaches of Articles 13, 14, and the security requirements in Annex I — with the actual rules set by each Member State and notified to the Commission. Article 64 is not among the provisions Article 71(2) lists as applying early; none of the three official pages this article consulted mentions fines, or says whether, between now and December 2027, a breach of Article 14 would be penalized.
How Far the Platform Has Gotten So Far
ENISA describes the platform that just launched as an ‘initial operating capability,’ not a finished product. Its FAQ lists what is still missing: at launch the interface supports English only; there is no application programming interface, so notifications must be submitted through the platform's own interface; and voluntary reporting under Article 15 — covering vulnerabilities, threats, incidents, and near-misses — is not yet available, so the platform currently accepts only the mandatory notifications required under Article 14. ENISA says voluntary reporting will be introduced in a ‘future phase’; for the application programming interface and additional language versions, it says only that they may be considered, or will be reviewed, in the next phase — neither comes with a timetable.
The platform is also not a channel for consumer complaints: the current release accepts only the mandatory notifications manufacturers submit under Article 14, and a submission from someone who is not a manufacturer may be marked invalid. ENISA also openly acknowledges a known flaw: the 72-hour countdown timer actually shows a due time 48 hours after the 24-hour early warning is submitted, so in some cases a notification shows as overdue before 72 hours have actually elapsed since the manufacturer became aware; ENISA stresses that the timer's display does not replace the legal obligation itself.
There are also identity limits on who may submit a notification: each manufacturer may have only one ‘Primary’ designated representative (Primary AR) and up to 20 ‘Secondary’ designated representatives (Secondary ARs), who must log in with an EU Login account protected by multi-factor authentication — the platform currently has no additional corporate-identity verification mechanism. The Primary and Secondary representatives of the same manufacturer can all see that manufacturer's notifications, regardless of who originally submitted them; only unsubmitted drafts stay in each representative's own account. The official pages this article consulted do not disclose how many notifications, or how many registered manufacturers, the platform has had since launch, so this article does not state either figure.
Frequently asked questions
My device wasn't bought in the EU — does this reporting obligation have anything to do with me?
Article 2 of the Cyber Resilience Act sets its scope as connected products ‘made available on the market’ in the EU with a connection to a device or network. As of the official pages this article consulted on September 17, 2026, none of them says anything specifically about Taiwan or markets outside the EU; Article 14(7) only addresses which country's window a notification is sent to (including how that is decided when a manufacturer has no main establishment in the EU), which has nothing to do with where the user is located. What decides whether the rule reaches a given case is still the market scope in Article 2. This article can only cite how the provisions themselves define that scope — it cannot tell a reader whether their own device counts.
I found a vulnerability in my own device — can I report it through this platform?
No. ENISA's FAQ states plainly that the current version of the platform accepts only the mandatory notifications manufacturers submit under Article 14; a notification from someone who is not a manufacturer may be flagged as invalid by the platform, and ENISA suggests contacting your own country's CSIRT directly instead. Article 15 was designed to give anyone a voluntary reporting channel, but ENISA says this feature is not yet available in the platform's current version.
Once a notification is made, will I find out what happened to my device?
The official pages this article consulted set no specific notification deadline. Article 14(8) requires the manufacturer, once it becomes aware, to inform affected users — and where appropriate all users — of the vulnerability or incident, and, where necessary, of any mitigation or corrective measures they can take; but the provision only states that a CSIRT may notify users on the manufacturer's behalf if the manufacturer fails to inform them ‘in a timely manner’ — it does not set how quickly notice must go out, nor its language or channel. The vulnerability itself is not automatically made public either: under Article 17(5), ENISA adds a publicly known vulnerability to the European vulnerability database only once a corrective measure is available and the manufacturer agrees.
Does the manufacturer still have to report an older device I've had for years?
Based on the official pages, yes. ENISA's FAQ states that the Article 14 reporting obligation ‘will apply from 11 September 2026 to all products with digital elements falling within the scope of the CRA, including products that were placed on the market before 11 December 2027.’ That differs from the Regulation's usual transitional rule, under which an older product only has to meet the new requirements if it is later ‘substantially modified’ — the reporting obligation is not limited that way, and applies regardless of how old the product is.
What else changes after December 11, 2027?
At that point the Cyber Resilience Act applies in full, in principle, including parts this article has not covered in detail: Article 13(8) requires manufacturers to set a support period of at least five years — unless the product's expected use is shorter than five years, in which case the support period matches that expected use instead; Article 13(9) requires every security update issued during the support period to remain available for at least ten years after release, or for the rest of the support period, whichever is longer; and Article 24(3) extends the same reporting obligation to open-source software stewards, limited to the extent they are involved in developing the product. The official pages this article consulted group all of this under the Regulation's main obligations, distinct from the Article 14 reporting obligation that is already in effect.
How much can a company be fined for failing to report?
Article 64 sets a ceiling: up to €15 million, or 2.5% of an offending undertaking's total worldwide annual turnover for the preceding financial year, whichever is higher, for breaches of Articles 13, 14, and the security requirements in Annex I — but the actual penalty rules are set by each Member State and notified to the European Commission. Article 64 itself is not among the provisions Article 71(2) lists as applying early, and none of the three official pages this article consulted mentions fines or says whether — or how — a breach of Article 14 would be penalized between now and December 11, 2027.
2026 Tech News Roundup: Key Points on Hardware, Platforms, Telecom, and Regulation2026 Tech News Roundup: Key Points on Hardware, Platforms, Telecom, and RegulationThis site's 2026 tech-news explainers in five groups — hardware, platforms, computing infrastructure, Taiwan policy, EU regulation: iPhone Duo and September hardware, M6/M5 Ultra, Snapdragon 8 Elite Gen 6, Project Zenith, Pixel Drop, App Store subscriptions, WordPress and Synology patches, NVIDIA, 6G, the Taiwan–Matsu cables, the sovereign AI corpus, the Cyber Resilience Act, the KIDS Act and Apple's EU terms. No purchase advice; vendor claims attributed; official sources and check dates.Read the full article
Apple Announces New EU App Business Terms: A 5% Core Technology Commission, and Alternative Payments Alongside Apple In-App PurchaseApple Announces New EU App Business Terms: A 5% Core Technology Commission, and Alternative Payments Alongside Apple In-App PurchaseOn August 18, 2026, Apple announced new EU App Store business terms: the Core Technology Fee becomes a 5% Core Technology Commission, commissions run 26%/20%/15% by payment method, and apps may offer Apple In-App Purchase alongside alternative payments. Primary updates take effect October 1, 2026, for EU storefronts only. Checked against Apple's own announcements and support pages on September 17, 2026.Read the full article
Lifestyle
Apple Announces New EU App Business Terms: A 5% Core Technology Commission, and Alternative Payments Alongside Apple In-App Purchase
On August 18, 2026, Apple announced new EU App Store business terms: the Core Technology Fee becomes a 5% Core Technology Commission, commissions run 26%/20%/15% by payment method, and apps may offer Apple In-App Purchase alongside alternative payments. Primary updates take effect October 1, 2026, for EU storefronts only. Checked against Apple's own announcements and support pages on September 17, 2026.
Lifestyle
Cloudflare launches Traces in public beta: site operators can follow every step a request takes through the platform on one timeline
On October 2, 2026, Cloudflare announced the public beta of Cloudflare Traces. Website operators and developers using Cloudflare can see a request pass through security rules, caching, routing and the origin server on a single timeline, making it easier to find why a request was blocked or slowed. New pricing takes effect on December 1, 2026. Information comes from the official Cloudflare blog.
Lifestyle
Cloudflare launches Web Search API via AI Gateway, requiring search partners to follow its crawler rules
On October 2, 2026, Cloudflare announced a Web Search API that lets AI agents query live web information through AI Gateway. The first partners are Ceramic.ai, Exa and Linkup. Cloudflare says these partners' crawlers must meet its Verified bots requirements and cite sources. This matters both to developers building AI applications and to website owners whose content may be crawled.
Lifestyle
Cloudflare open-sources Streamline: a demo of using its cloud services to add graphics to live streams and burn subtitles into videos
On October 2, 2026, Cloudflare launched and open-sourced Streamline, a developer playground showing how developers can combine Stream, Workers, Containers and Durable Objects to build their own video processing pipelines, such as adding graphics to live streams in real time or adding subtitles to videos. This article explains what it is, how it works, its limitations, and what it means for viewers and developers.
Articles that cite this one
- WordPress 7.1.2 Patches a Critical Core Vulnerability: Patched Versions by Branch and How to Check Your Site
- Synology Advisory SA-26:13: Two Unauthenticated 9.8 Flaws — Check Your Version Before Updating
- European Commission Adopts KIDS Act Proposal: No Social Accounts Under 13, Own Account at 15
- Apple Announces New EU App Business Terms: A 5% Core Technology Commission, and Alternative Payments Alongside Apple In-App Purchase
- 2026 Tech News Roundup: Key Points on Hardware, Platforms, Telecom, and Regulation
Latest travel guides

GuideTokyo
Where to Stay in Tokyo: Comparing Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza, Plus Airport Access, Accommodation Tax, and Luggage Delivery
Where should you stay in Tokyo? Compare Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza by the same criteria: access from Narita and Haneda, transit routes, nearby attractions, neighborhood character, and who each area suits. Includes a comparison table, a Yamanote Line diagram, Tokyo’s accommodation tax as verified in 2026/9 (changing to 3% in 2027/4), and Airport TA-Q-BIN luggage shipping rules.
- Budget
- Hotels

GuideTokyo
How to Choose Tokyo Transit Passes: Are Suica, Welcome Suica, the Tokyo Subway Ticket, and the JR Pass Worth It?
On a first Tokyo trip, start with an IC card and pay per ride (Welcome Suica has no deposit and is valid for 28 days). If you take four or more subway rides in a day, add a 72-hour Tokyo Subway Ticket for 2,000 yen; a JR Pass is never worthwhile if you stay in Tokyo and do not go to Kansai. See what TOURIST PASMO, Suica on iPhone, and the Tokyo Metro day pass do and do not cover, with a decision chart. Prices verified in September 2026.
- Transport
- Budget

GuideTokyo
Tokyo Disneyland and DisneySea Guide: Ticket Prices, Fantasy Springs, Disney Premier Access (DPA), Standby Pass, and Which Park to Choose for Your First Visit
Tokyo Disney one-day Passport prices vary: most weekdays in 9/2026 cost ¥9,900 and weekends ¥10,900. At 14:00 daily, tickets go on sale for the same date two months later. Free Priority Pass is no longer on the official service list; only paid Disney Premier Access (¥1,000–3,500 per person per use) shortens waits. Covers hours, the 25th anniversary, Standby Pass, Entry Request, Fantasy Springs access and first-visit park choice; checked on the official site in 9/2026.
- Itineraries
- Family
Sources
- European Commission: Cyber Resilience Act Reporting Obligations Page · Checked:
- ENISA Press Release: The CRA Single Reporting Platform Is Launched · Checked:
- ENISA: Single Reporting Platform Frequently Asked Questions · Checked:
- EUR-Lex: Full Text of Regulation (EU) 2024/2847 (Cyber Resilience Act) as Published in the Official Journal · Checked: